?
Solved

Configuration Problems with a Cisco Site-to-Site VPN

Posted on 2009-04-04
1
Medium Priority
?
250 Views
Last Modified: 2012-05-06
I'm trying to add a site-to-site VPN connection to a Cisco 1711 that already has a working EZvpn setup.  I have been over this to the point that I'm just not seeing what I'm missing.  It is failing to establish IKE.  Any pointers as to what I'm missing would be most appreciated.  This is the Hub router config.
20090404-jdn-r01-sanitized.txt
0
Comment
Question by:NelsonS74
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 9

Accepted Solution

by:
Donboo earned 2000 total points
ID: 24067915
You named you static map "dynmap" and gave the reference to your dynamic-map (which you also called dynmap) as first priority whatever static you enter after here dosnt matter as they will match your dynamic map and as the site-to-site dosnt have any groupname to match a ISAKMP will not be established.

crypto map dynmap (Static map name) 1 ipsec-isakmp dynamic dynmap (dynamic map name)

So change your dynamic map to a higher prio like 65000 and add you static as a lower number. that should get you to first base :P

Example of static map with dynamic map:
!
crypto dynamic-map DYN-VPN 1
 set transform-set groupname1
 set isakmp-profile groupname1-profile
 reverse-route
!
crypto dynamic-map DYN-VPN 2
 set transform-set groupname2
 set isakmp-profile groupname2-profile
 reverse-route
!
crypto map VPN 1 ipsec-isakmp
 set peer x.x.x.x
 set transform-set CUST1-L2L
 set pfs group2
 set isakmp-profile CUST1-L2L
 match address CUST1-L2L
!
crypto map VPN 2 ipsec-isakmp
 set peer y.y.y.y
 set transform-set CUST2-L2L
 set pfs group2
 set isakmp-profile CUST2-L2L
 match address CUST2-L2L
!
crypto map VPN 65000 ipsec-isakmp dynamic DYN-VPN
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question